A U.S. Army soldier was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution for hacking into telecommunications companies and stealing call and text metadata belonging to more than 100 million AT&T customers in 2024.

Cameron John Wagenius, 22, admitted to the intrusions while stationed at a U.S. Army base in South Korea, where he operated under the cybercriminal handle Kiberphant0m. Federal prosecutors said he worked with three alleged co-conspirators to pull data from several large customers of the cloud storage service Snowflake that had left credentials exposed and did not enforce multi-factor authentication, a policy Snowflake has since changed. In October 2024, Wagenius claimed on cybercrime forums to have stolen metadata such as source and destination numbers, timestamps and call durations for tens of millions of AT&T customers.

Prosecutors said Wagenius also claimed to have breached more than a dozen telecommunications companies worldwide, including Verizon's Push-to-Talk business, and publicly extorted them with the threat of publishing the stolen data. He further admitted to re-extorting victims and threatening to disclose national security secrets. After AT&T paid the extortion group a $370,000 Bitcoin ransom and co-conspirator Conor Riley Moucka was arrested, Wagenius posted what he said were AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, along with schematics allegedly taken from the National Security Agency.

Kenneth Schuchman, 28, of Vancouver, Washington, assisted the extortion efforts, prosecutors said. Schuchman pleaded guilty in 2019 to running the Satori botnet, a collection of hacked Internet-of-Things devices used in large-scale distributed denial-of-service attacks. Moucka, also known as Judische, of Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026. John Erin Binns, an American living in Turkey who is also wanted over a 2021 T-Mobile breach that exposed data on at least 76 million customers, is still facing charges tied to the Snowflake thefts.

Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service, said his agency opened the investigation alongside the FBI, the Army Criminal Investigative Division and the U.S. Secret Service after learning an active-duty soldier with a secret clearance was involved in cybercrime and extortion. He said the case was serious from the outset because it involved an insider threat. Wagenius was arrested in late 2025 after KrebsOnSecurity reported he was likely a soldier in South Korea, and he pleaded guilty to all counts in two federal indictments.

A Sept. 19 sentencing memo from Seattle federal prosecutors said Wagenius cooperated almost immediately but was later caught violating Bureau of Prisons computer use policies while awaiting sentencing. Records show he used other inmates' email accounts in September 2025 to ask an email recipient to prompt a commercial AI tool for Windows 10 Enterprise privilege escalation vulnerabilities, an exploit for a D-Link command injection flaw tracked as CVE-2023-45208, and instructions for building a prison antenna. Prosecutors said he also asked for research on escaping prison, framed the requests as book research, and that the government found no evidence he deployed the vulnerabilities. Despite the scale of the stolen data, prosecutors said Wagenius earned only about $1,500 from selling it.

More cybersecurity news from TechManNews.